A new AIFM can have a compliance manual, a risk matrix and a calendar of controls before its first fund starts operating. The harder question comes at the first management meeting: why are these the right controls, what has actually been tested, and what still needs a decision?
A useful Compliance Risk Assessment (CRA) and Compliance Monitoring Plan (CMP) answer that question together. The CRA explains where the firm is exposed. The CMP turns that assessment into work that someone can execute, review and evidence.
Start with the right regulatory perimeter
This article is written for a Luxembourg AIFM preparing for authorisation or beginning operations under the fully authorised regime. A registered AIFM has a different perimeter; the two should not be treated as interchangeable. The CSSF maintains separate guidance for authorisation and registration.
The regulatory anchor is Circular CSSF 18/698: point 235 requires regular assessment and control of compliance risk. Point 259 recommends describing a risk-based CMP, its activities and timetable in the compliance summary report. Points 256 and 257 address regular reporting and the annual summary. The workflow below is our practical recommendation, not a prescribed CSSF template or launch timetable.
Give the CRA and CMP different jobs
The CRA should explain a decision: why an exposure deserves attention, what mitigates it and how much uncertainty remains. A label such as “medium” is useful only if another officer can understand the reasoning behind it.
The CMP should describe an executable test: what will be checked, by whom, when, against which criteria and using which evidence. “Review delegation” is a topic. “Check whether the selected delegate reports were received, challenged and followed up” is the beginning of a test.
Here, CRA means compliance risk assessment. It does not replace the separate work on portfolio risk, liquidity or the AML/CFT risk assessment. Make the connections visible, but preserve each assessment’s purpose and ownership.
Build the first CRA around the business you will run
Start with a short operating-model inventory: funds and strategies, asset types, investor profile, distribution footprint, delegates, internal responsibilities and key systems. A private-equity manager using external valuation specialists will need different questions from a manager operating a liquid strategy with frequent dealing.
For each relevant area, write the exposure as a concrete failure scenario. “Conflicts of interest” is too broad on its own. “A related-party valuation input is accepted without independent challenge” gives the reviewer something to assess.
We recommend recording five things against each scenario:
- the applicable obligation and the activity it affects;
- the potential consequence and the basis for the inherent-risk rating;
- the mitigating arrangement, its owner and the evidence supporting it;
- the residual-risk judgement and any uncertainty; and
- the event that should trigger a reassessment.
At launch, distinguish a control that has been designed from one that has operated successfully. A signed procedure shows the intended process. It does not demonstrate that exceptions were identified or escalated. Where execution evidence does not yet exist, record that limitation rather than giving the control the benefit of an untested assumption.
Turn each priority into a test someone can perform
Build the first CMP from the assessment rather than copying a complete calendar from another firm. Give priority to significant exposures, applicable fixed deadlines and controls whose operation is still unproven. Explain the chosen frequency; a risk score alone cannot determine every review date.
A workable control record should identify the population, review period, sampling approach where relevant, test steps, evidence requested, expected result, reviewer and escalation route. Assign a realistic execution date and allow time for review and remediation.
Keep operational controls distinct from the compliance function’s testing of those controls. The person who performs an activity and the person who challenges its effectiveness should not become indistinguishable in the plan.
An example: from delegate oversight risk to a CMP test
Consider a fictional newly authorised AIFM that delegates portfolio management. Its CRA identifies a risk that a significant mandate exception reaches the firm too late. A contract and reporting schedule exist, but the AIFM has limited evidence of how the reporting works in practice.
The initial CMP could include the following test. This is an illustration, not a regulatory minimum sample or frequency.
- Population: reports expected from the selected delegate during the review period, together with the associated exception correspondence.
- Test: compare expected and received reports, inspect evidence of challenge, and trace reported exceptions to an owner and documented follow-up.
- Evidence: the reporting schedule, dated reports, review notes and the exception record.
- Conclusion: state what was tested and what failed. If the first reporting cycle has not occurred, record that execution is not yet testable.
- Follow-up: assign the gap, set a remediation date and determine whether the CRA or the next test needs to change.
The resulting record is more informative than a green cell beside “delegate oversight”. It explains what the firm knows and what it still needs to establish. Our article on delegate oversight explores that subject further.
Use the first monitoring cycle to challenge the assumptions
During the first cycle, compare the plan with what the team could actually execute. Missing evidence may reveal an unclear responsibility, a weak contractual reporting arrangement or simply a control scheduled before the relevant activity occurred. Those are different problems and need different responses.
A useful management discussion covers the significant exposures, work completed, work overdue or not yet testable, material findings, remediation owners and decisions required. Keep the link back to the CRA visible. An officer should be able to see why an unresolved finding matters without opening a separate spreadsheet.
Revisit the assessment when the operating model changes. A new strategy, distribution market, delegate or material incident should prompt a question about scope and coverage, rather than waiting automatically for the next annual refresh.
Five questions before calling the framework operational
- Can we explain why each priority appears in the CMP?
- Could another qualified reviewer execute the test from the instructions?
- Do we distinguish evidence received from evidence actually reviewed?
- Does every open finding have an owner, a next step and a target date?
- Can the officers see what remains uncertain and which decisions are theirs?
For a new AIFM, these questions provide a more useful starting point than the number of controls in the library. A manageable plan with clear reasoning can be improved after each cycle. A large inherited checklist can remain difficult to defend even when every row has a date.
Where Klavius fits
Klavius brings the control library, compliance risk assessment, monitoring plan, findings and action plans into one regulatory oversight platform. Officers can review proposed assessments and keep their decisions alongside the work. The practical aim is continuity between a risk identified, a control scheduled and a finding followed up.
The judgement about your firm’s perimeter and acceptable risk remains with your officers. If you are setting up your first cycle, the Compliance Risk module is the starting point for a working session on your CRA and CMP.
Sources
- CSSF, Circular CSSF 18/698, points 235 and 256 to 259.
- CSSF, Authorisation of an AIFM.
- CSSF, Registration of an alternative investment fund manager and subsequent amendments.
